Privacy policy
Last updated: 18 September 2026
In short: tunnl. is built so that we cannot read your messages and files. We only store what is needed to run the service, no IP addresses, and delete almost everything automatically after a short time. No ads, no tracking, no third-party analytics tools.
1. Who is responsible?
xoox ag, Unter Sidhalden 16, 6010 Kriens, Switzerland
E-mail: hi@xooxag.com · or directly via an echo in tunnl.
We process personal data under the Swiss Federal Act on Data Protection (FADP). Where the GDPR applies to people in the EU/EEA, we rely on Art. 6(1)(b) GDPR (providing the service you use) and Art. 6(1)(f) GDPR (legitimate interest in secure, abuse-free operation).
2. The principle: end-to-end encryption in the browser
Messages, files and file names are encrypted in your browser before they are transmitted (AES-256-GCM). The key is in the link after the # sign. Browsers never send that part to a server, so it appears in no server log. The token identifying a conversation is also placed after the #. An optional password never leaves your browser.
Our server therefore only holds encrypted data that neither we nor our hosting provider can read. This also applies to the conversation list in your account: it is encrypted with a key that only exists in your browser.
How this works technically is explained under How tunnl. works.
3. What data we process
3.1 Messages and conversations (with or without an account)
- Encrypted content of messages and attached files.
- Check values (hashes) of the links and the access key, so only authorised people can retrieve a conversation. Links cannot be derived from hashes.
- The account option (“seelisbrg”, “gotthrd”) with its expiry date and, if unlocked with a gift code, the link to that code. Codes themselves are stored only as a hash.
- Technical data without content: creation time (rounded to the hour), time of individual messages and whether they were read or edited, number of messages, expiry time, whether a password is set, number of wrong attempts, size and expiry of files.
3.2 Abuse protection – without IP addresses
To slow down mass requests we count requests per day. For this, your IP address is combined in memory with a secret that changes daily into a one-way value (HMAC). Only this value and a counter are stored, for at most 24 hours. tunnl. does not store the IP address itself, and the value cannot be traced back to it.
3.3 Account (optional)
- E-mail address: stored encrypted. It is only decrypted to send e-mails (sign-in codes, alerts) and in our account administration, e.g. to block an account in case of abuse. A check value (HMAC) is used to find your account.
- Sign-in codes: only as a check value, valid for 15 minutes, deleted after one day at the latest.
- Session: a cookie (see section 4). The server only holds a check value of the session ID and its expiry.
- Account key: a check value and a copy encrypted with your recovery code. We do not know the code.
- Encrypted conversation list with links and labels you choose.
- Display name: a name you set yourself is stored in plain text. It is visible to the other person once you save a conversation to your account. Without a name, a random fantasy name is shown.
- Passkeys: public key, identifier, the name you give it, creation and last-use date. Fingerprint or face data never reach us; they stay on your device.
- Attachments: link to your account, size, status and expiry. Name and file type only encrypted.
- Account creation date and day of last use.
- E-mail alerts (only if you turn them on): whether they are on, your language and when an alert was last sent. Alerts contain neither content nor names.
- Block note: if we block an account for abuse, we store the time and a short internal reason.
3.4 Branded sending (“gotthrd” option)
With this option tunnl. can send the notification e-mail on your behalf. For that we process:
- Sender profile: company name, reply address and logo – in the clear, because they have to be visible in the e-mail. The logo travels inside the e-mail and is never fetched from a server.
- Recipient address, subject and covering text: they reach us only at the moment of sending, are used for the e-mail and are not stored. We count how many such e-mails an account sends per day for the daily limit.
- The link containing the key: if tunnl. sends the e-mail, the link passes through our server at that moment. We do not store it. With a password on the message the link alone is useless to anyone – including us.
- Address book and text blocks: encrypted with your account key. We cannot read them.
3.5 Echo (messages to us)
An echo is a normal encrypted conversation. Access to it is sealed in your browser for our team account, so only we can open it. For the daily limit of 5 echoes we store which account an echo came from and delete this after two days at the latest. We see your display name like any other conversation partner.
3.6 Usage statistics without personal reference
To run and improve tunnl. we count events as daily totals: page views per page, approximate number of visitors (using the anonymous daily value from section 3.2), created and picked-up messages, replies (each with or without an account), uploads, new accounts, sign-ins and throttled requests. Plus the domain of the referring website (without path), a campaign tag from the link (e.g. ?ref=newsletter), the device type (phone, tablet, computer) and the language. Individual visits, people or accounts cannot be identified from this. We delete the totals after 400 days. No cookies and no third-party services are used for this.
3.7 Logs of our hosting provider
As with any website, our hosting provider logs technical access data such as IP address, time, requested address and browser identifier, as well as e-mail delivery (recipient address, time). This serves the operation and security of the servers. These logs contain no content, no keys and no indication of which conversation was opened. They are kept and deleted according to the provider's retention periods; we do not analyse them.
4. Cookies and browser storage
- Cookie
tr_acc– only when you sign in: keeps your session (12 hours, 30 days with “Remember device”). Technically necessary. - Local browser storage: your account key (permanent with “Remember device”, otherwise until the browser is closed), your light/dark choice, whether browser alerts are on, the last reported message state and short-lived helper values (e.g. where to return after sign-in; conversations opened in this tab before signing in, until they are added to your account). This data does not leave your browser. Alerts about new messages are generated by your browser itself; no third-party push service is used.
We use no tracking, advertising or analytics cookies and embed no third-party content (no external fonts, scripts or maps).
5. How long we keep data
| Data | Deletion |
|---|---|
| First message | when opened; if unopened, after the chosen pickup time (1 minute to 3 days, 14 days for echoes) |
| 🔥 messages | after being shown once |
| Conversation | 30 days after the last activity, after 10 wrong attempts or on request; afterwards only the status without content remains for 7 days |
| Files | after 1, 3 or 7 days – up to 12 months with the “seelisbrg”/“gotthrd” option –, earlier on request; 🔥 files after the first download; unsent files after 1 hour. If a file is attached again, it stays stored until the last period has expired |
| Abuse counters | after 24 hours at most |
| Sign-in codes · sessions | on expiry (codes after 1 day at the latest) |
| Usage statistics (daily totals) | after 400 days |
| Account with list, name, passkeys | when you delete the account (in your account under “Delete account”) |
| Sender profile · address book · text blocks | until you change or delete them; at the latest with the account |
| Recipient address, subject and link of a branded e-mail | not at all – they are only used for sending |
Our hosting provider makes backups. Deleted, still encrypted data may remain in them until the respective backup expires.
6. Who receives data
- Hosting: METANET AG, Josefstrasse 218, 8005 Zurich, Switzerland. According to the provider, the servers are located in data centres in Switzerland. METANET processes the data on our behalf.
- E-mail: sign-in codes and – if turned on – new message alerts are sent via our hosting provider's mail server and delivered by the e-mail service you use.
- Authorities: only if we are legally obliged. Even then we can only hand over what we hold – content only in encrypted form.
We do not sell data or pass it on for advertising. We do not transfer data abroad.
7. Security
All connections use HTTPS. Content is end-to-end encrypted, passwords are processed with PBKDF2 (600,000 rounds), e-mail addresses are stored encrypted. tunnl. does not protect against a compromised device, or against someone with the complete link opening the message or passing content on.
8. Your rights
You can request information about your data and its correction, deletion or handover. You can delete your account yourself at any time; conversations delete themselves automatically or on request. Because content is encrypted, we can only provide information about data we can read – such as your e-mail address, display name, passkey names and timestamps.
Write to us at hi@xooxag.com. You also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), or in the EU/EEA with the supervisory authority of your country of residence.
9. Changes
When tunnl. changes, we update this policy. The version published here applies.

